Replies: 7 comments 2 replies
-
Short: There is a reason why it works this way. I am not sure I understand your question:
Long: When you run
|
Beta Was this translation helpful? Give feedback.
-
Could you go deeper here? "Some drop-in system config file are needed to ensure apparmor profile are loaded before some services" Its possible to load apparmor as pid1? I mean before init system? |
Beta Was this translation helpful? Give feedback.
-
We simply need to ensure the profiles are loaded into the kernel before the start of some services are loaded (see the systemd directory). It simply means we need to ensure that systemd is going to start apparmor.service before services such as Note: there are other methods to actually load the profiles into the kernel before even starting systemd, however, it is not used (yet) in this project. |
Beta Was this translation helpful? Give feedback.
-
Userspace tools like aa-complain .*. Still works inside apparmor.d directory ? aa-enforce .*. Too? After installed it is in enforcement or in complain mode by default? |
Beta Was this translation helpful? Give feedback.
-
All aa tools work as expected. As explained in the documentation, the profile are in complain mode by default, then you can put then in enforce mode: https://apparmor.pujol.io/enforce/ |
Beta Was this translation helpful? Give feedback.
-
Udisk makes trouble, when usb stick plugged in Os= artix linux. Every profile are in complain mode Only works again when sudo aa-teardown and module is unloaded. |
Beta Was this translation helpful? Give feedback.
-
sudo aa-disable dbus-daemon-launch-helper Helped. But no log output.. |
Beta Was this translation helpful? Give feedback.
-
Can we do this on already running apparmor protected system?
Im asking because why go pkg and recompile of apparmor lsm is needed and additonal install notes required.
Thanks and
Best regards
Beta Was this translation helpful? Give feedback.
All reactions